[jboss-jira] [JBoss JIRA] (WFLY-5022) The server requires JASPI authentication even if no security-constraint is defined

Stuart Douglas (JIRA) issues at jboss.org
Thu Aug 13 19:59:02 EDT 2015


    [ https://issues.jboss.org/browse/WFLY-5022?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13098222#comment-13098222 ] 

Stuart Douglas commented on WFLY-5022:
--------------------------------------

We are going to deal with this by disabling proactive auth by default

> The server requires JASPI authentication even if no security-constraint is defined
> ----------------------------------------------------------------------------------
>
>                 Key: WFLY-5022
>                 URL: https://issues.jboss.org/browse/WFLY-5022
>             Project: WildFly
>          Issue Type: Bug
>          Components: Security, Web (Undertow)
>    Affects Versions: 10.0.0.Alpha6
>            Reporter: Josef Cacek
>            Assignee: Stuart Douglas
>            Priority: Critical
>
> If JASPI authentication is configured in security domain, then the server requires authentication even if no security-constraint is defined for web application which uses the security domain.
> With the classic authentication is the behavior correct.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)


More information about the jboss-jira mailing list